Information on romance scams and scammers.
#217778 by Faizan Docherty Fri Sep 05, 2014 10:49 am
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 114.111.89.162
Originating ISP: Internet Content Provider
City: n/a
Country of Origin: Japan
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.70.74.40 with SMTP id q8csp38584pdv;
Wed, 3 Sep 2014 22:59:23 -0700 (PDT)
X-Received: by 10.70.53.65 with SMTP id z1mr4925067pdo.74.1409810363578;
Wed, 03 Sep 2014 22:59:23 -0700 (PDT)
Return-Path: <[email protected]>
Received: from relay.mailchannels.net (nov-007-i624.relay.mailchannels.net. [46.232.183.178])
by mx.google.com with ESMTP id gm6si1460333pac.92.2014.09.03.22.59.20
for <snipped>;
Wed, 03 Sep 2014 22:59:23 -0700 (PDT)
Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 46.232.183.178 as permitted sender) client-ip=46.232.183.178;
Authentication-Results: mx.google.com;
spf=softfail (google.com: domain of transitioning [email protected] does not designate 46.232.183.178 as permitted sender) [email protected];
dkim=pass [email protected]
X-Sender-Id: _forwarded-from|183.79.150.46
Received: from r8-chicago.webserversystems.com (ip-10-204-4-183.us-west-2.compute.internal [10.204.4.183])
by relay.mailchannels.net (Postfix) with ESMTPA id 71390120EBD
for <snipped>; Thu, 4 Sep 2014 05:59:16 +0000 (UTC)
X-Sender-Id: _forwarded-from|183.79.150.46
Received: from r8-chicago.webserversystems.com ([UNAVAILABLE]. [10.220.170.51])
(using TLSv1 with cipher DHE-RSA-AES256-SHA)
by 0.0.0.0:2500 (trex/5.2.13);
Thu, 04 Sep 2014 05:59:17 GMT
X-MC-Relay: Forwarding
X-MailChannels-SenderId: _forwarded-from|183.79.150.46
X-MailChannels-Auth-Id: wwwh
X-MC-Ingress-Time: 1409810356646
Received: from web101415.mail.kks.yahoo.co.jp ([183.79.150.46]:37584)
by r8-chicago.webserversystems.com with smtp (Exim 4.82)
(envelope-from <[email protected]>)
id 1XPQ4b-0001E3-Af
for <snipped>; Thu, 04 Sep 2014 00:59:12 -0500
Received: (qmail 34237 invoked by uid 60001); 4 Sep 2014 05:59:00 -0000
DKIM-Signature: <snipped>
DomainKey-Signature: <snipped>;
Message-ID: <[email protected]>
X-YMail-OSG: <snipped>
Received: from [114.111.89.162] by web101415.mail.kks.yahoo.co.jp via HTTP; Thu, 04 Sep 2014 14:58:59 JST
X-Mailer: YahooMailWebService/0.8.111_56
X-YMail-JAS: <snipped>
Date: Thu, 4 Sep 2014 14:58:59 +0900 (JST)
From: Esther Falogo <[email protected]>
Reply-To: Esther Falogo <[email protected]>
Subject: Hello my dear, My name is Esther Falogo, 28 years old single lady, a Canadian citizen. I would like to share more details about each other, I am willing to build a sincere relationship with a man who is honest and sincere, caring and loving, and after reading your profile here I developed interest on you. If you are interested kindly email me so that we can share some more pictures and details about each other. Looking forward to chat with you soon. Esther Falogo,
To: "[email protected]" <[email protected]>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="-2007480563-1972490580-1409810339=:33764"
X-Spam-Status: No, score=2.9
X-Spam-Score: 29
X-Spam-Bar: ++
X-Ham-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.

Content preview: [...]

Content analysis details: (2.9 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[183.79.150.46 listed in list.dnswl.org]
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(mabellkabila[at]yahoo.co.jp)
-0.0 SPF_PASS SPF: sender matches SPF record
0.0 RP_MATCHES_RCVD Envelope sender domain matches handover relay domain
0.0 HTML_MESSAGE BODY: HTML included in message
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
2.0 DCC_CHECK Detected as bulk mail by DCC (dcc-servers.net)
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different
freemails
X-Spam-Flag: NO
X-MC-Forward: <snipped>
X-AuthUser:


***Email message in the subject line***

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
Advertisement

Who is online

Users browsing this forum: Majestic-12 [Bot] and 284 guests